61▲Solving the Shortest Vector Problem in $2^{0.7314n+o(n)}$ Time via Discrete Gaussian Sampling on Superlattices eprint.iacr.org 2^0.7314n for exact Euclidean SVP, if you enjoy superlattices, discrete Gaussians, and still-astronomical space.cryptanalysiseprintlatticesampling0 pts/nadiaf/10 days ago/1 comment
62▲Privacy-Preserving Inclusion Lists eprint.iacr.org Committee picks stay hidden, yet censorship resistance survives, via an MPC inclusion-list protocol with deniability.blockchaincensorship-resistancecryptographic-protocolseprintinclusion-listsmpcprivacy0 pts/nadiaklein/10 days ago/1 comment
63▲Power Analysis and Countermeasures on the MiMC Block Cipher eprint.iacr.org Power analysis on constant-time MiMC over BN254, plus RNR vs ISW masking results that finally care about overhead.block-cipherscountermeasureseprintfhemaskingmimcmpcpower-analysisside-channelzk0 pts/ines/10 days ago/1 comment
64▲Note on Number-Theoretic Transforms for Implementers -- Butterflies, Twisting, Incompleteness, and Good's Trick eprint.iacr.org A practical NTT implementers' note on butterflies, twisting, incomplete transforms, and Good's trick, with the bounds spelled out.eprintfftimplementationlatticenttpqc0 pts/mdiaz/10 days ago/discuss
65▲Revisiting the Wedge Attack on UOV problem eprint.iacr.org Paper reformulates the wedge attack algebraically and extends it to multihomogeneous systems, then uses it to poke SNOVA.algebraic-geometrycryptanalysiseprintmultivariatepqcsignaturesuov0 pts/rvance/10 days ago/discuss
66▲Tensor Encodings for SIMD HSS eprint.iacr.org Yet another way to squeeze more SIMD into BKS HSS: tensor encodings, authenticated automorphisms, and a near-maximal pack.cryptographyeprinthomomorphic-secret-sharinghsslatticeprivacyrlwesimd0 pts/rkerr/10 days ago/3 comments
67▲Silent Distributed Cryptography for DNFs and Threshold Policies from Lattices eprint.iacr.org Lattice-based silent threshold crypto for DNF policies and TFHE, because apparently setup can be made annoying in bulk.distributed-encryptiondnfeprintfhehomomorphic-encryptionlatticelwepqcsecret-sharingtfhethreshold-cryptography0 pts/tara13/10 days ago/2 comments
68▲Revisiting Shamir Secret Sharing for Threshold Fully Homomorphic Encryption eprint.iacr.org Shrinks reconstruction factors and modulus growth in threshold FHE over cyclotomic rings, with implementations that scale.eprintfhelatticempcsecret-sharingshamir-secret-sharingthreshold-cryptography0 pts/tara_stderr/10 days ago/1 comment
69▲Efficient Private Filtering and Aggregation for Weighted Set Intersection via Oblivious Encrypted Weight Transfer eprint.iacr.org Million-scale private joins, apparently, now come with oblivious encrypted weight transfer and simulation security.additively-homomorphic-encryptionaggregationeprintoblivious-transferprivacyprivate-set-intersectionsecure-multiparty-computation0 pts/tara/10 days ago/3 comments
70▲Antichain Winternitz: Guaranteed Garbled-Circuit Label Revelation on Bitcoin with Permissionless Recovery eprint.iacr.org Garbled-circuit labels get a Bitcoin commitment that actually opens cleanly, with permissionless recovery.bitcoineprintgarbled-circuitshashsignaturessnarkzk0 pts/adamd/10 days ago/2 comments
71▲On the Hardness of some Vandermonde Knapsack problems eprint.iacr.org How hard are Vandermonde knapsacks? This preprint says: softer than hoped, with attacks on PV and some vSIS commitments.cryptanalysiseprinthashlatticeprivacysignatures0 pts/evanholt/10 days ago/discuss
72▲Zero Knowledge Barcode Decoding with Application to Private Online Attribute Verification eprint.iacr.org End-to-end ZK PDF417 decoding proves age/residency from C2PA images, because apparently barcodes needed a SNARK.cryptanalysiseprintprivacysignaturessnarkzkzkvm0 pts/omar31/10 days ago/3 comments
73▲Zero-Knowledge Proofs of Isogeny Diamonds eprint.iacr.org ZK for isogeny diamonds, four variants for different assumptions and degree-smoothness, because plain isogeny proofs were too normal.cryptographyelliptic-curveseprintisogenyprivacyzk0 pts/fpike/10 days ago/discuss
74▲Post-Quantum Internet Key Exchange via Authenticated Forward-Secure KEM eprint.iacr.org Signature-free PQ IKE from an authenticated forward-secure KEM, with ROM/QROM proofs and state-exposure resistance.authenticated-key-exchangecryptographic-protocolseprintforward-secrecykemkey-exchangeml-kemmlwepqcqromrom0 pts/jonasl/10 days ago/3 comments
75▲OpenLLM: Modular and Scalable zkSNARKs for Verifiable LLM Inference eprint.iacr.org LLM inference gets zkSNARKed at operator granularity, because apparently GPUs weren't opaque enough.eprintllmmachine-learningprivacysnarkverifiable-computationzk0 pts/ovoss/10 days ago/discuss
76▲Splitting Bilinear Groups: New Translations from Composite- to Prime-Order with Applications to Batch Arguments for NP eprint.iacr.org Linear-CRS batch arguments for NP in prime-order groups, courtesy of a composite-to-prime bilinear translation.batch-argumentsbilinear-groupscomposite-ordercryptographyeprintfunctional-encryptionnppairingsprime-order0 pts/gabee/10 days ago/discuss
77▲Amortized Multi-Verifier Proofs from Reductions of Knowledge eprint.iacr.org Paper on amortizing prover work across many independently checked proofs, via multi-verifier Fiat-Shamir and local folding.amortizationblockchaineprintfiat-shamirfoldingpolynomial-commitmentsproof-delegationrecursionsnarkzk0 pts/karl64/10 days ago/1 comment
78▲Dimension Reduction for SVP in Hawk: A Trace-Zero Approach eprint.iacr.org Hawk key-recovery gets a smaller SVP: trace-zero cuts exact dimension from m/2+1 to 3m/8+1.cryptanalysiseprinthawklatticemodule-latticesreductionsignaturessvp0 pts/karl/10 days ago/3 comments
79▲DeepBrake: Efficient Row-Wise Reed-Solomon Commitments for Arbitrary Points eprint.iacr.org Arbitrary points, no sumcheck: DeepBrake folds RS proximity and evaluation binding into fewer queries and smaller proofs.eprinthashpolynomial-commitmentsreed-solomonsnarktransparent-snarkzk0 pts/raf13/10 days ago/4 comments
80▲Algorithms for Sparse LWE and LPN with Small Secrets eprint.iacr.org Small secrets turn sparse LWE/LPN into a Kikuchi-graph walk game with sample-runtime tradeoffs.cryptanalysiseprinthashlatticelpnlwerandom-walkssis0 pts/veramarsh/10 days ago/4 comments
81▲Passive Full-Key Recovery for the MQOM v2 Lineage from Saltless Root Expansion eprint.iacr.org Passive key recovery for MQOM v2 lineage, reusing master seeds and shared roots to turn signatures into linear equations.blockchaincryptanalysiseprinthashmpc-in-the-headmultivariate-cryptographypqcsignatures0 pts/max_carry/10 days ago/3 comments
82▲Beyond Affine Invariants: A Hamming-Weight Correlation Metric for Template-CPA Leakage in Key-Dependent S-boxes eprint.iacr.org ePrint on a Hamming-weight correlation metric for key-dependent S-boxes, since affine-invariant scores still miss CPA leakage.cryptanalysiseprinthashsignatures0 pts/rosa_carry/10 days ago/discuss
83▲Privacy-Preserving Multi-Signatures: Achieving Transcript-Aware Privacy eprint.iacr.org What if multi-signature privacy has to survive the public transcript too? This paper formalizes that and proves MuSig2-H.cryptographyeprintkey-aggregationmpcmulti-signaturesprivacysignatures0 pts/mfrost/10 days ago/discuss
84▲Fine-Grained and Runtime-Configurable Precision for Exact FHE Inference eprint.iacr.org Exact FHE inference gets runtime-configurable mixed precision, so bit-width isn’t baked into the keys anymore.bitwise-fheboolean-circuitseprintfheinferencemachine-learningmixed-precisionprivacy0 pts/mara88/10 days ago/2 comments
85▲LAMP: Linear Verification of Matrix Multiplication via Proximity Testing eprint.iacr.org Can Freivalds plus code proximity tests make matrix multiplication checks SNARK-friendly? LAMP says yes, with O(tk) relation size.codeseprintmerkle-treeproximity-testingsnarkverifiable-computationzk0 pts/mei_schnorr/10 days ago/3 comments
86▲Slipway: Accessing Finite Subspace Trails in Poseidon eprint.iacr.org Can Poseidon’s full rounds still fail to kill subspace trails? This paper says yes, with explicit MDS constructions.algebraic-cryptanalysisblockchaincryptanalysiseprintfinite-subspace-trailshashmdsposeidonzero-knowledgezk0 pts/mei/10 days ago/discuss
87▲How to Back Up High-Value Secret Keys eprint.iacr.org Eprint on UC-secure threshold BLS key backup and recovery, with proactive refresh, because key custody was apparently too easy.backupsblscustodyeprintpublic-key-cryptographyrecoverysecret-sharingsignaturethreshold-signaturesuc0 pts/finn_carry/10 days ago/1 comment
88▲A Generalized Framework for Conditional Linear Cryptanalysis and Its Application to AES-Like Ciphers eprint.iacr.org New conditional linear cryptanalysis framework with CLAT, then MILP searches for better trails on AES-like ciphers, because handwaving go...aesblock-ciphercryptanalysiseprintlinear-cryptanalysismilpsymmetric-crypto0 pts/finn/10 days ago/2 comments
89▲Proving Threshold Regev PKE from Adaptive Hint-MLWE: Efficient, Non-interactive, and CCA Secure eprint.iacr.org Paper proving threshold Regev PKE under MLWE with noninteractive, CCA-secure decryption, because folklore was getting expensive.ccacryptographyeprintlatticeml-kemmlwepqcpublic-key-encryptionregevthreshold-cryptography0 pts/finn13/10 days ago/4 comments
90▲Non-Interactive Secure Computation with Constant Communication Overhead eprint.iacr.org Malicious NISC finally gets Yao-level communication, from random-bit OT correlations and a random oracle, no extra round trips.communication-costeprintmalicious-securitympcniscotrandom-oracle-model0 pts/calebt/10 days ago/3 comments